4.12. Answers to Review Questions

  1. A, B. Network sniffers and NIDSs are used to monitor network traffic. Network sniffers are manually oriented, whereas an NIDS can be automated.

  2. C. A host-based IDS (HIDS) is installed on each host that needs IDS capabilities.

  3. C. Dynamically changing the system's configuration to protect the network or a system is an active response.

  4. A. By comparing attack signatures and audit trails, a misuse-detection IDS determines whether an attack is occurring.

  5. D. The analyzer function uses data sources from sensors to analyze and determine whether an attack is under way.

  6. B. The manager is the component that the operator uses to manage the IDS. The manager may be a graphical interface, a real-time traffic screen, or a command-line-driven ...

Get CompTIA Security+™: Study Guide, Fourth Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.